This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Toronto

From OWASP
Revision as of 01:49, 6 September 2018 by Yuk Fai Chan (talk | contribs) (Announcing September & October 2018 events)

Jump to: navigation, search

OWASP Toronto Chapter.jpg


OWASP Toronto

Welcome to the Toronto chapter homepage. The chapter is managed by Andre Rochefort, Yuk Fai Chan, Opheliar Chan and Nish Bhalla.


Participation

OWASP Foundation (Overview Slides) is a professional association of global members and is open to anyone interested in learning more about software security. Local chapters are run independently and guided by the Chapter_Leader_Handbook. As a 501(c)(3) non-profit professional association your support and sponsorship of any meeting venue and/or refreshments is tax-deductible. Financial contributions should only be made online using the authorized online chapter donation button. To be a SPEAKER at ANY OWASP Chapter in the world simply review the speaker agreement and then contact the local chapter leader with details of what OWASP PROJECT, independent research or related software security topic you would like to present on.

Sponsorship/Membership

Btn donate SM.gif to this chapter or become a local chapter supporter. Or consider the value of Individual, Corporate, or Academic Supporter membership. Ready to become a member? Join Now BlueIcon.JPG


The mailing list archive can be accessed from here.

Our chapter's Meetup.com page is can be accessed here.

Chapter Supporters

We would like to thank the following organizations for their support and contribution to the local Toronto chapter!

Gold Local Chapter Supporter

Hewlett Packard Enterprise

Silver Local Chapter Supporter

Checkmarx

Global Contributing Corporate Member & Local Event Supporter

Security Compass

Local Event Supporter

Amazon

Local Event Supporter

Shopify



Date/Time: Monday September 17, 2018, 6:00 PM to 8 PM EDT

Location: 80 Spadina Avenue, Toronto, ON

Space is limited, so please RSVP on our chapter event page.


6-7 PM

"iOS App runtime manipulation" with Ivan Rodriguez

In this talk, we'll learn how to decrypt and extract an iOS application from a device, and use reverse engineering techniques to manipulate the app at runtime.

Ivan Rodriguez is an Application Security Engineer at Shopify with a mobile development background, currently working in application security.


7-8PM

"Auditing/Pen Testing Android Apps" with Kristina Balaam

As our world becomes more dependent on mobile devices, it's important to understand the risks we may unknowingly introduce to users through the applications we build. In this talk, we'll cover general Android security best practices, discuss tools for auditing your own applications to find vulnerabilities, and resources for continued learning.

Kristina is a Security Intelligence Engineer at Lookout where she reverse engineers mobile malware. Prior to Lookout, she worked as an Application Security Engineer at Shopify focusing mostly on Android mobile security. Kristina graduated with a Bachelor of Computer Science from McGill University in 2012, and is currently pursuing a MSc. in Information Security Engineering from the SANS Institute of Technology. She blogs about computer security on Twitter, Instagram and Youtube under the handle @chmodxx.



Date/Time: Monday October 1, 2018, 6:00 PM to 8 PM EDT

Location: 80 Spadina Avenue, Toronto, ON

Space is limited, so please RSVP on our chapter event page.


Azure Cloud Security Workshop

By: Tanya Janca, OWASP Ottawa Chapter Co-Leader


Tanya Janca is a senior cloud developer advocate for Microsoft, specializing in application security; evangelizing software security and advocating for developers through public speaking, her open source project OWASP DevSlop, and various forms of teaching via workshops, blogs and community events. As an ethical hacker, OWASP Project and Chapter Leader, software developer and professional computer geek of 20+ years, she is a person who is truly fascinated by the ‘science’ of computer science.


You can find out more about Tanya here:

@SheHacksPurple

http://devslop.co/

https://medium.com/@shehackspurple

https://www.slideshare.net/TanyaJanca

https://www.youtube.com/channel/UCyxbNw11fMUgoR3XpVYVPIQ

https://www.twitch.tv/shehackspurple


Have you ever wondered how security is different ‘in the cloud’? Where do you store your certificates? Your keys? Your connection strings? How can you see what’s going on with your resources? How do you patch? Where can you see your server configs other important information? How do you manage an security incident? How do you even know that you’re having an incident?

This first half of this workshop will be a demo where the audience follows along, the second part will be for audience members to build things and secure them, in Azure.


Demo will include:

  • Complete Azure Security Centre walkthrough
  • Policy and compliance, including subscription coverage
  • Resource Security Hygiene
  • Azure Security Centre Recommendations (mitigation of one or more items, dependent on time)
  • Threat Protection, Alerts and Threats
  • Applying System Updates
  • Key Vault


Audience Participation (people who do not have a laptop can follow along with the teacher)

  • Create a DevOps project, from scratch, and publish to the internet. (20-30 mins)
  • Turn on Security Centre (5 mins)
  • Check your security configurations and settings to ensure your new app is safe. (10 mins)
  • More as time permits.


What you will need if you want to participate after the demo:

  • A laptop running any modern operating system (Mac OS, Windows, Linux)
  • Modern web browser (Safari, Edge, Chrome, FireFox)
  • Wi-fi and internet
  • An activated Azure Trial. Please activate your trial before the workshop. The workshop will not wait if you have not activated your trail.


To activate your free Azure trail for this workshop please go here: https://aka.ms/Azure-Cloud-Security-Workshop

>> If you have previously used your free Azure Trail you will not be able to have another one for this workshop.

>> You will need to use a credit card to activate your trial, but the trial itself is free for 30 days, up to $200. We will use up to $30 of your credit with this workshop.